Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does PrestaShop Work in China? PIPL Cross-Border, ICP Filing & Data Residency

PrestaShop is an open-source, self-hosted PHP store whose MySQL database holds your customers' PII, orders and behavior. Run it on offshore hosting and serving a China storefront is a PIPL cross-border transfer; the storefront still needs an ICP filing and China payment runs through a licensed domestic path. A compliance-first look at the residency, ICP and payment exposure — and the in-country self-host lever.

Does PrestaShop work in China?

Deployed the common way — on offshore hosting — PrestaShop keeps your China shoppers' customer PII, orders and behavior abroad, the public storefront isn't ICP-filed, and China payment still needs a licensed domestic path; but because PrestaShop is open-source and self-hostable, the lawful fix is to run the store in-country.

PrestaShop is an open-source PHP application (core licensed OSL-3.0) whose MySQL database holds your customers' names, addresses, phone numbers, emails, full order histories and browsing behavior — personal information about people in mainland China. Run that store on offshore hosting and you, the handler, are making a cross-border transfer of personal information under PIPL (notice, a separate consent and a transfer mechanism, Articles 38–40). The public storefront is an internet service that needs an ICP filing bound to a licensed mainland host, and China's dominant mobile wallets run through a licensed domestic payment path a foreign platform can't provide directly. The lawful lever is not to make an offshore storefront reachable — it is to self-host the open-source engine in-country so customer PII and orders stay on the mainland, ICP-file and deliver the storefront in-country, and route China payment through a licensed domestic path (21YunBox is advisory on payment licensing).

This is a risk map, not a verdict — which filing you need and how PIPL applies turns on your entity, your data volumes and whose data it is. Our China team can map your exposure →

What PrestaShop's own documentation says about China

FactPrimary source
PrestaShop is open-source software you self-host. PrestaShop's own repository describes it as "an Open Source e-commerce web application" written in PHP, and its license file sets the core under OSL-3.0 (modules under AFL-3.0). You run it on a web server you provide, so you choose the infrastructure — which means you can run the same engine on in-country, ICP-filed hosting and keep customer PII and orders on the mainland. PrestaShop on GitHub — README and LICENSE.md (github.com/PrestaShop/PrestaShop), retrieved 2026-10-10
Your store's data lives in a database you host. PrestaShop's system requirements call for "MySQL 5.7 minimum or MariaDB 10.2 minimum" and PHP (8.1 recommended) on a web server you provide; the shop's customer accounts, orders and behavior all persist in that database. Because the database is on infrastructure you choose, where your China shoppers' personal information rests is decided by where you host — and that can be in-country. PrestaShop Developer Documentation — System requirements for PrestaShop 8 (devdocs.prestashop-project.org), retrieved 2026-10-10
A China store on offshore hosting is a PIPL cross-border transfer. If your PrestaShop store runs outside the mainland, the accounts, addresses, orders and payment identifiers of your China shoppers are carried across the border — a cross-border transfer of personal information that, as the handler, you must support with notice, a separate consent and a transfer mechanism (CAC security assessment, standard contract or certification), PIPL Articles 38–40, on a lawful basis under Articles 13 and 23. PIPL Articles 38–40 and 13/23; 21YunBox — Cross-border data transfers under PIPL, retrieved 2026-10-10
The storefront needs an ICP filing, and high-volume handlers must store China data in-country. A public China storefront is an internet information service that needs an ICP filing (备案) bound to a licensed mainland host — which an offshore-hosted, foreign-domain storefront cannot satisfy as-is — and a critical information infrastructure operator or high-volume handler must store China-collected personal information in the mainland under Cybersecurity Law Article 39 (formerly Article 37). State Council Order No. 292 and MIIT Order No. 33 (ICP filing); Cybersecurity Law Article 39 (formerly Article 37); 21YunBox — China's Cybersecurity Law, retrieved 2026-10-10

Sources verified by the 21YunBox compliance team on 2026-10-10.

For a mainland-China audience, whether PrestaShop “works” is settled well before anyone times the storefront: it turns on where your shoppers’ data is allowed to live, whether the public storefront can carry an ICP filing, and how China payment is settled. An online store is the most regulated data you hold — customer names, shipping addresses, phone numbers, emails, full order histories and browsing behavior — and in PrestaShop all of it rests in the MySQL database behind the shop. Helpfully, PrestaShop is open-source under the OSL-3.0 license and you run the PHP application on hosting you choose, which makes this a genuine data-residency lever rather than a reachability problem. Four prongs decide the rest: a cross-border transfer of your customers’ personal information, an ICP filing for the public storefront, China payment through a licensed domestic path, and in-country storage once you are a high-volume handler.

PrestaShop's GitHub repository showing it described as an Open Source e-commerce web application written in PHP, under the OSL-3.0 license you can run on your own in-country hosting
"PrestaShop is an Open Source e-commerce web application" — PrestaShop's own repository publishes the platform as a self-hostable PHP application under the OSL-3.0 license, the engine you can run in-country so customer data stays on the mainland. Source: PrestaShop on GitHub

PrestaShop in China at a glance

What decides it In PrestaShop's own terms — and China's law
What it holds A PrestaShop store keeps customer accounts, names, shipping and billing addresses, phone numbers, emails, full order histories and browsing behavior in its MySQL database. For a China-facing shop that describes people in China — it is personal information, not a cache.
Where it runs PrestaShop is self-hosted: you install the PHP application on hosting you choose. Run it on the offshore hosting most foreign merchants already use and your China shoppers' data rests abroad — a cross-border transfer (数据出境) under PIPL Articles 38–40. The same open-source core can instead run in-country.
The storefront is a public site A storefront that faces the public in China is an internet information service that needs an ICP filing (备案) bound to a licensed mainland host. A storefront served from offshore hosting on a foreign domain cannot be filed as-is.
Payment and residency China's dominant mobile wallets run through licensed domestic payment, a regulated activity a foreign platform cannot provide directly; PrestaShop's official checkout module is built on an international processor. A critical information infrastructure operator or high-volume handler must also store China-collected data in the mainland — Cybersecurity Law Article 39 (formerly Article 37).
The axis — and the lever Reachability is not the question. Because PrestaShop is OSL-3.0 open source and self-hostable, the lawful lever is to run the store on in-country hosting so customer PII and orders stay on the mainland, ICP-file the storefront, and route China payment through a licensed domestic path. 21YunBox is advisory on payment licensing.

What you actually hold — customer PII, orders and behavior

A store is not a pipe; it is your system of record. PrestaShop keeps the shop’s state in a MySQL (or MariaDB) database you provision, and that database is where your customers live: registered accounts with names, shipping and billing addresses, phone numbers and email addresses; full order and invoice histories; the payment identifiers and tokens your gateways return; wish lists, carts and the browsing behavior the shop records; and the messages customers send through it. For a China-facing store, every one of those fields describes a person in mainland China, so the database is a store of personal information — not a transient cache. Where that personal information rests is decided by one thing: where you run the PHP application and its database. Install PrestaShop on offshore hosting and it rests abroad; install the same open-source engine on in-country hosting and it rests on the mainland. That location — not how quickly the storefront paints — is what China’s law reads.

Three doors: cross-border customer data, an ICP-filed storefront, and licensed payment

Once you accept that the database is your customers’ personal information, three doors open in sequence.

The cross-border door. Run your China store on hosting outside the mainland and you have carried your shoppers’ personal information across the border — a cross-border transfer (数据出境) under China’s Personal Information Protection Law. The handler — you, not PrestaShop — must give notice, obtain a separate consent for the transfer, and clear one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification (Articles 38–40), on a lawful processing basis to begin with (Articles 13 and 23). If you are a critical information infrastructure operator or a high-volume handler — thresholds an active online store crosses readily — personal information collected in China must additionally be stored in the mainland under Cybersecurity Law Article 39 (formerly Article 37) (the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged), a residency duty no offshore region satisfies.

The storefront door. A storefront that faces the public in China is an internet information service, and a public site in China carries an ICP filing (备案) duty bound to a licensed mainland hosting resource. A storefront served from offshore hosting on a foreign domain cannot be filed as-is; a compliant China store needs an in-country, ICP-filed delivery path. Because a store transacts, the filing points toward the commercial track rather than a basic recordal — confirm the exact path for your entity.

The payment door. Accepting China’s dominant mobile wallets runs through licensed domestic payment, a regulated non-bank-payment activity a foreign platform cannot provide directly; PrestaShop’s official checkout module is built on an international payment processor, not a China domestic wallet path. China’s E-Commerce Law and its consumer-PII rules layer further platform duties on top. 21YunBox is advisory here — it routes you to a licensed domestic payment path and does not itself hold a China payment license.

Reaching the storefront isn’t the question — a compliant in-country store is

PrestaShop installs on any LAMP host and the storefront is reachable; connectivity was never the obstacle. The obstacle is residency and licensing, and the honest fix is to keep your customers’ data on the mainland rather than to make an offshore store reachable. Because PrestaShop is open-source under the OSL-3.0 license and you choose where it runs, you can stand up the exact same engine on in-country hosting, so customer accounts, orders and behavior never leave China; minimize and pseudonymize what the store collects while you are at it, since a field you never store is a field you never have to transfer. What this is not: shipping the database to an offshore store and relabeling it local. Localizing means the store’s data genuinely rests on an in-country path, behind an ICP-filed storefront, with China payment settled through a licensed domestic path.

This is a risk map, not a verdict: whether a localization duty applies, which cross-border mechanism fits, which ICP track your store needs, and how China payment is best licensed turn on your entity, your data volumes and whose data it is — settle the specifics with counsel before you build.

The lawful path — map, localize, deliver

Map. We inventory the customer PII, orders, behavioral data and payment flows your PrestaShop store holds, where the application and its database run today, whether the storefront is ICP-filed, how China payment is handled, and the consent basis behind it all.

Localize. We keep your China-customer PII and orders in-country — standing up a self-hosted deployment of the open-source PrestaShop engine on mainland infrastructure so the database stays on the mainland — then minimize and pseudonymize what the store collects, obtain the Article 13/23 consent, and route China payment through a licensed domestic path (21YunBox is advisory on payment licensing). 21YunBox never uses or suggests circumvention of any kind.

Deliver. The storefront still faces the public in China, so it carries an ICP filing duty and needs compliant, in-country delivery — the 21YunBox Optimizer, set in front of the stack you already run, with no rebuild and no migration. PrestaShop stays your store; we add the lawful China boundary around it so it runs legally and compliantly for your users in China.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Can we run PrestaShop in China legally?
Yes — and because PrestaShop is open-source and self-hostable, you have a real advantage. The honest path is to run the store on in-country hosting so your China customers' personal information and orders stay on the mainland, obtain an ICP filing for the public storefront bound to a licensed mainland host, and route China payment through a licensed domestic path. What none of this is: shipping the database offshore and calling it local. Treat the exact filing track and your residency duties as specifics to confirm for your entity and data volumes.
Is it a problem that our PrestaShop store's data sits outside China?
Treat it as a PIPL question to assess with counsel, not a yes/no. For shoppers in mainland China, the accounts, addresses, orders and payment identifiers that rest on offshore hosting are a cross-border transfer of personal information — requiring notice, a separate consent and a transfer mechanism — and a critical information infrastructure operator or high-volume handler must store China-collected data in the mainland (Cybersecurity Law Article 39, formerly Article 37). Because PrestaShop is self-hostable, keeping that data in-country is within your control.
Can 21YunBox help make our PrestaShop store work in China?
Yes. PrestaShop stays your store — we don't replace it. Our China team maps your PIPL, ICP and payment exposure for your entity and your shoppers, stands up an in-country, self-hosted deployment of the open-source engine so customer PII and orders stay on the mainland, delivers the storefront on ICP-filed infrastructure, and advises on routing China payment through a licensed domestic path (21YunBox is advisory on payment licensing). Get in touch to work through your specific case.

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.